<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic  Hi Srinath, ASA2 has incmp in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-ping-switch-behind-directly-connected-asa/m-p/2559743#M203018</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Srinath,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA2 has incmp inspect enabled.&lt;/P&gt;&lt;P&gt;These ASA's are in my home lab.&lt;/P&gt;&lt;P&gt;Can this be due to nating?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
    <pubDate>Thu, 27 Nov 2014 16:37:12 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2014-11-27T16:37:12Z</dc:date>
    <item>
      <title>unable to ping Switch behind directly connected ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-switch-behind-directly-connected-asa/m-p/2559741#M203016</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is setup ASA1-e0/0----192.168.1.171----------------e0/0---192.168.1.174&amp;nbsp; ---ASA2-----et0/1----10.2.0.1------fa1/0/1------10.2.0.2---Switch&lt;/P&gt;&lt;P&gt;I am pinging from ASA1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA1#&amp;nbsp; ping 10.2.0.2&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 10.2.0.2, timeout is 2 seconds:&lt;BR /&gt;?????&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Logs show&lt;/P&gt;&lt;P&gt;Nov 26 2014 21:24:26: %ASA-6-302020: Built outbound ICMP connection for faddr 10.2.0.2/0 gaddr 192.168.1.171/56999 laddr 192.168.1.171/56999&lt;/P&gt;&lt;P&gt;Nov 26 2014 21:24:36: %ASA-6-302021: Teardown ICMP connection for faddr 10.2.0.2/0 gaddr 192.168.1.171/56999 laddr 192.168.1.171/56999&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA2 logs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nov 26 2014 21:28:43: %ASA-6-302020: Built inbound ICMP connection for faddr 192.168.1.171/9199 gaddr 10.2.0.2/0 laddr 10.2.0.2/0&lt;BR /&gt;Nov 26 2014 21:28:53: %ASA-6-302021: Teardown ICMP connection for faddr 192.168.1.171/9199 gaddr 10.2.0.2/0 laddr 10.2.0.2/0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this default behaviour ? or&lt;/P&gt;&lt;P&gt;i need some config change to fix this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:08:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-switch-behind-directly-connected-asa/m-p/2559741#M203016</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T05:08:38Z</dc:date>
    </item>
    <item>
      <title>Hi Mahesh, Can you please</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-switch-behind-directly-connected-asa/m-p/2559742#M203017</link>
      <description>&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please check if you have ICMP inspect on ASA2?&lt;/P&gt;&lt;P&gt;You should see "inspect icmp" in the output of "show run policy-map" under the global_policy.&lt;/P&gt;&lt;P&gt;If not, then run "fixup protocol icmp" from config mode and try again. If it still fails, please attach 'show tech' from both ASAs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Srinath&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2014 07:21:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-switch-behind-directly-connected-asa/m-p/2559742#M203017</guid>
      <dc:creator>Srinath R</dc:creator>
      <dc:date>2014-11-27T07:21:39Z</dc:date>
    </item>
    <item>
      <title> Hi Srinath, ASA2 has incmp</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-switch-behind-directly-connected-asa/m-p/2559743#M203018</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Srinath,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA2 has incmp inspect enabled.&lt;/P&gt;&lt;P&gt;These ASA's are in my home lab.&lt;/P&gt;&lt;P&gt;Can this be due to nating?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2014 16:37:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-switch-behind-directly-connected-asa/m-p/2559743#M203018</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2014-11-27T16:37:12Z</dc:date>
    </item>
    <item>
      <title>Hi Mahesh, Could you please</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ping-switch-behind-directly-connected-asa/m-p/2559744#M203019</link>
      <description>&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please share the output of 'show tech' from both ASAs?&lt;/P&gt;&lt;P&gt;It would be easier to find the root cause from the outputs.&lt;/P&gt;&lt;P&gt;Based on the logs, it does not look like the ASA is dropping the packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Srinath&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2014 02:06:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ping-switch-behind-directly-connected-asa/m-p/2559744#M203019</guid>
      <dc:creator>Srinath R</dc:creator>
      <dc:date>2014-11-28T02:06:14Z</dc:date>
    </item>
  </channel>
</rss>

